tcp 22 > tcp 22
Nikolaj I. Potanin
nikolaj at drweb.ru
Wed Jul 2 00:19:35 PDT 2003
> Jul 1 13:34:35 fbsd /kernel: ipfw: 1400 Accept TCP xxxxxx:22 yyyyy:22 in via
> ed1
> where xxxxxx is the attacker's IP and yyyyy is my box.
> Also, as you can see, the connection is made from port 22 to port 22, which is
> odd.
http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=22441 -
maybe this could explain your case?
--
Nikolaj I. Potanin, SA http://www.drweb.ru
ID Anti-Virus Lab (SalD Ltd) nikolaj at drweb.ru
St. Petersburg, Russia ph.: +7-812-3888624
More information about the freebsd-security
mailing list